Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-2101
HistoryApr 17, 2024 - 5:00 a.m.

CVE-2024-2101 WordPress Plugin Salon Booking System < 9.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)

2024-04-1705:00:02
WPScan
github.com
4
wordpress
plugin
salon booking system
unauthenticated
stored
cross-site scripting
xss
admin
customers
appointment
mobile phone
sanitize
escape
attack

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the ‘Mobile Phone’ field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the ‘Customers’ page and the malicious script is executed in the admin context.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:salonbookingsystem:salon_booking_system:-:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "salonbookingsystem",
    "product": "salon_booking_system",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "9.6.3"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-2101